Alignment means the domain that passed SPF or DKIM is the same domain the recipient sees in the From line.
Key points
- DMARC passes only when at least one of SPF (Sender Policy Framework) or DKIM (DomainKeys Identified Mail) passes and its domain aligns with the From domain [1].
- SPF alignment compares the Return-Path domain with the From domain; DKIM alignment compares the signature's d= domain with the From domain [1].
- Relaxed mode is the default, so news.example.com aligns with example.com; the aspf and adkim tags can require strict, exact matches [1].
- Gmail requires bulk senders to align the From domain with either the SPF or the DKIM domain [2].
- Microsoft's high-volume sender rules ask for alignment with SPF or DKIM, and preferably both [3].
- A vendor that signs with its own domain passes DKIM but fails alignment, a frequent cause of DMARC failures in Email Authentication reports.
Why alignment exists
SPF (Sender Policy Framework) and DKIM (DomainKeys Identified Mail) each authenticate a domain, but neither one looks at the From header that a person reads. SPF checks the envelope sender, and DKIM checks whatever domain signed the message. A spammer could pass both using their own domain while putting a bank's address in the From line. DMARC closes that gap by requiring that the authenticated domain line up with the From domain [1]. Only one aligned pass is needed, which gives senders flexibility: a message relayed through a forwarder may lose its SPF pass but keep an aligned DKIM signature. Alignment is what turns two technical checks into a statement about the identity a recipient actually sees, and it is the heart of modern Email Authentication. It is also a precondition for BIMI, which builds on an enforced DMARC policy.
Relaxed versus strict alignment
Under relaxed alignment, the default, two domains align if they share the same organizational domain. Mail signed by mail.example.com with a From address at example.com passes. Under strict alignment, set with adkim=s or aspf=s in the DMARC record, the domains must match exactly [1]. RFC 9989 changed how receivers find the organizational domain, replacing the Public Suffix List with a walk up the DNS tree, but the effect for most domains is the same. Strict mode suits organizations that want tight control over which subdomains may send. Most teams leave alignment relaxed, which lets marketing, support and outreach tools use subdomains while still passing. A Secondary Sending Domain, however, is a separate organizational domain and needs its own aligned setup.
Fixing alignment failures
The typical failure looks like this in a DMARC report: SPF passes and DKIM passes, but DMARC fails. That means both checks passed for some other domain, usually the Email Service Provider (ESP) or tool that sent the mail. The fix is to configure the tool to sign with your own domain, often called custom DKIM or domain authentication, and, where supported, to use a custom Return-Path on a subdomain you control. Gmail's guidelines treat this as a hard requirement for bulk senders [2], and Outlook applies the same logic to domains sending more than 5,000 messages a day [3]. Reviewing aggregate reports after adding any new sending service, from a CRM to a billing platform, catches these problems before they affect Sender Reputation.
Related terms
Outreach without the busywork.
PineLead finds new B2B prospects every day, qualifies them against your criteria and writes the first email in your voice. You approve — PineLead sends.
Start free with 100 credits →